CA Item | Policy 1 | Policy 2 | Policy 3 | Policy 4 | Policy 5 | Policy 6 | Policy 7 | Policy 8 | Policy 9 |
Name | MFA for User access control | Block Legacy Authentication | Physical location access control | Device Compliance Check – MacOS Devices | Device Compliance Check – Windows Devices | MAM-WE App Protection Compliance Check – Mobile Devices | Block unsupported devices | Block high risk users | Require password change for medium risk users |
PolicyID | | | | | | | | | |
Status | Enabled | Enabled | Enabled | Enabled | Enabled | Enabled | Enabled | Enabled | Enabled |
Users | | | | | | | | | |
UsersInclude | All | All | All | All | All | All | All | All | All |
UsersExclude | | | | | | | | | |
Cloud apps or actions | | | | | | | | | |
ApplicationsIncluded | All | All | All | All | All | All | All | All | All |
ApplicationsExcluded | | | | | | | | | |
userActions | | | | | | | | | |
AuthContext | | | | | | | | | |
Conditions | | | | | | | | | |
UserRisk | | | | | | | | high | medium |
SignInRisk | | | | | | | | high | |
PlatformsInclude | | | | macOS | windows | android,
iOS | windowsPhone,
linux | | |
PlatformsExclude | | | | | | | | | |
LocationsIncluded | | | All | | | | | | |
LocationsExcluded | | | UK | | | | | | |
ClientApps | all | exchangeActiveSync,
other | all | all | all | all | all | all | all |
DevicesIncluded | | | | | | | | | |
DevicesExcluded | | | | | | | | | |
DeviceFilters | | | | | | | | | |
GrantControls | | | | | | | | | |
BuiltInControls | mfa | block | block | compliantDevice | compliantDevice | compliantApplication | block | block | passwordChange |
TermsOfUse | | | | | | | | | |
CustomControls | | | | | | | | | |
GrantOperator | OR | OR | OR | OR | OR | OR | OR | OR | AND |
SessionControls | | | | | | | | | |
SessionControlsAdditionalProperties | | | | | | | | | |
ApplicationEnforcedRestrictionsIsEnabled | True | | | | | | | | |
ApplicationEnforcedRestrictionsAdditionalProperties | | | | | | | | | |
CloudAppSecurityType | | | | | | | | | |
CloudAppSecurityIsEnabled | | | | | | | | | |
CloudAppSecurityAdditionalProperties | | | | | | | | | |
DisableResilienceDefaults | | | | | | | | | |
PersistentBrowserIsEnabled | | | | | | | | | |
PersistentBrowserMode | | | | | | | | | |
PersistentBrowserAdditionalProperties | | | | | | | | | |
SignInFrequencyAuthenticationType | primaryAndSecondaryAuthentication | | | | | | | | |
SignInFrequencyInterval | timeBased | | | | | | | | |
SignInFrequencyIsEnabled | True | | | | | | | | |
SignInFrequencyType | days | | | | | | | | |
SignInFrequencyValue | 7 | | | | | | | | |
SignInFrequencyAdditionalProperties | | | | | | | | | |